video-scriptwriting

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to automatically perform local directory enumeration upon activation. It specifies running an ls command on hidden system directories, including ~/.claude/skills/, ~/.agent/skills/, and ~/.agents/skills/, to detect companion skills. This constitutes unsolicited local environment probing.\n- [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface for indirect prompt injection via its interview-driven workflow.\n
  • Ingestion points: User responses are collected across a 30-question framework defined in SKILL.md and references/interview-questions.md.\n
  • Boundary markers: The instructions do not provide delimiters or warnings to ignore instructions embedded within user answers.\n
  • Capability inventory: The skill is designed to generate and write structured YAML scripts incorporating this untrusted data.\n
  • Sanitization: There is no evidence of escaping or validation of user-provided content before interpolation into the final YAML output.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 08:29 AM
Security Audit — agent-trust-hub — video-scriptwriting